Tak som nakoniec z formátoval HD a nahodil Windows 7. Nainštaloval bežné programy a problém pretrváva! (NEODPOVEDA), aj ked zatial sporadicky!
Spravil som log zo RSIT Ešte spravim log zo Malwarebytes' Anti-Malware...
Logfile of random's system information tool 1.08 (written by random/random)
Run by harley1 at 2011-04-02 21:22:01
Microsoft Windows 7 Ultimate
System drive C: has 38 GB (69%) free of 55 GB
Total RAM: 1024 MB (19% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:24:07, on 2. 4. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Windows\mHotkey.exe
C:\Program Files\ClipMate7\clipmate.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Program Files\IncrediMail\Bin\ImApp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files\TechSmith\Snagit 10\Snagit32.exe
C:\Program Files\TechSmith\Snagit 10\TSCHelp.exe
C:\Program Files\TechSmith\Snagit 10\SnagPriv.exe
C:\Program Files\TechSmith\Snagit 10\snagiteditor.exe
C:\Program Files\Translate Client\translateclient.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\365dni\365dniNET.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
H:\Programy\SERVISNÉ SÚBORY\RSIT.exe
C:\Program Files\trend micro\harley1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKCU\..\Run: [ClipMate7] C:\Program Files\ClipMate7\clipmate.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [365dni] C:\Program Files\365dni\365dniNET.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Translate Client.lnk = C:\Program Files\Translate Client\translateclient.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Přidat do Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: K&ontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Služba Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
--
End of file - 9254 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}]
SnagIt Toolbar Loader - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll [2010-04-13 63304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll [2010-10-05 68280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-11-15 340384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-02-11 1246600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-04-02 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll [2010-10-05 191160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-11-15 340384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-11-15 340384]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - Snagit - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll [2010-04-13 206152]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\Windows\SOUNDMAN.EXE [2009-04-14 604704]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2006-10-09 90191]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2006-10-09 7741440]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2006-10-09 81920]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [2010-11-02 365336]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
""= []
"Adobe Acrobat Speed Launcher"=C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2010-11-15 36760]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2010-11-15 821144]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"CHotkey"=C:\Windows\mHotkey.exe [2002-07-23 477184]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-09-16 497648]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2011-04-02 2216960]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-12-20 443728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-12-20 443728]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2010-08-20 33120]
"ClipMate7"=C:\Program Files\ClipMate7\clipmate.exe [2009-01-31 3760424]
"IncrediMail"=C:\Program Files\IncrediMail\bin\IncMail.exe [2011-03-31 353736]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-04-02 3037696]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-03-08 17037704]
"365dni"=C:\Program Files\365dni\365dniNET.exe [2010-05-13 858624]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Translate Client.lnk - C:\Program Files\Translate Client\translateclient.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2010-10-05 228024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-04-02 21:17:27 ----D---- C:\Users\harley1\AppData\Roaming\Malwarebytes
2011-04-02 21:17:12 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-04-02 21:17:10 ----D---- C:\ProgramData\Malwarebytes
2011-04-02 21:17:03 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-04-02 21:17:01 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-02 21:00:59 ----D---- C:\Program Files\3D Image Commander
2011-04-02 21:00:14 ----D---- C:\Users\harley1\AppData\Roaming\Outertech
2011-04-02 20:57:28 ----D---- C:\Users\harley1\AppData\Roaming\COWON
2011-04-02 20:51:14 ----D---- C:\Program Files\Common Files\COWON
2011-04-02 20:51:06 ----D---- C:\Program Files\JetAudio
2011-04-02 20:45:38 ----A---- C:\ProgramData\mazuki.dll
2011-04-02 20:41:55 ----A---- C:\Windows\uninstall.exe
2011-04-02 20:37:39 ----D---- C:\Program Files\Barvy
2011-04-02 20:36:11 ----D---- C:\Program Files\GetDiz
2011-04-02 20:24:03 ----A---- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2011-04-02 20:23:56 ----D---- C:\Users\harley1\AppData\Roaming\365dni
2011-04-02 20:23:29 ----D---- C:\Program Files\365dni
2011-04-02 20:20:31 ----D---- C:\Users\harley1\AppData\Roaming\skypePM
2011-04-02 20:19:08 ----D---- C:\Users\harley1\AppData\Roaming\Skype
2011-04-02 20:17:52 ----D---- C:\Program Files\Common Files\Skype
2011-04-02 20:17:44 ----RD---- C:\Program Files\Skype
2011-04-02 20:17:17 ----D---- C:\ProgramData\Skype
2011-04-02 19:24:48 ----A---- C:\Windows\system32\drivers\sp_rsdrv2.sys
2011-04-02 19:24:47 ----D---- C:\Users\harley1\AppData\Roaming\Spyware Terminator
2011-04-02 19:23:57 ----D---- C:\ProgramData\Spyware Terminator
2011-04-02 19:23:57 ----D---- C:\Program Files\Spyware Terminator
2011-04-02 19:15:10 ----D---- C:\ProgramData\Martau
2011-04-02 19:14:42 ----D---- C:\Program Files\Total Uninstall 5
2011-04-02 19:08:35 ----D---- C:\Program Files\Vertus Fluid Mask 3
2011-04-02 19:04:06 ----D---- C:\ProgramData\VertusTech
2011-04-02 18:27:02 ----D---- C:\Program Files\Internet Download Manager
2011-04-02 18:24:58 ----D---- C:\Users\harley1\AppData\Roaming\VitySoft
2011-04-02 18:23:56 ----D---- C:\Users\harley1\AppData\Roaming\translateclient
2011-04-02 18:23:39 ----D---- C:\Program Files\Translate Client
2011-04-02 18:15:25 ----D---- C:\ProgramData\TechSmith
2011-04-02 18:15:23 ----D---- C:\Program Files\TechSmith
2011-04-02 18:13:42 ----D---- C:\Windows\5BCC634A58AD42F9B3C62EA52F81CF85.TMP
2011-04-02 18:13:34 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2011-04-02 18:05:55 ----D---- C:\ProgramData\IncrediMail
2011-04-02 18:05:55 ----D---- C:\ProgramData\IM
2011-04-02 18:05:55 ----D---- C:\Program Files\IncrediMail
2011-04-02 17:57:26 ----D---- C:\Users\harley1\AppData\Roaming\Thornsoft Development
2011-04-02 17:57:25 ----D---- C:\ProgramData\TEMP
2011-04-02 17:57:21 ----D---- C:\Program Files\ClipMate7
2011-04-02 17:50:07 ----D---- C:\Program Files\Adobe Media Player
2011-04-02 17:46:52 ----D---- C:\Program Files\Common Files\Adobe AIR
2011-04-02 17:37:45 ----D---- C:\Program Files\DynamicPhotoHDR5
2011-04-02 17:34:10 ----D---- C:\Users\harley1\AppData\Roaming\Ashampoo
2011-04-02 17:33:40 ----D---- C:\ProgramData\ashampoo
2011-04-02 17:32:09 ----D---- C:\Program Files\Ashampoo
2011-04-02 17:28:05 ----D---- C:\Users\harley1\AppData\Roaming\BSplayer PRO
2011-04-02 17:28:00 ----D---- C:\Program Files\Webteh
2011-04-02 17:25:13 ----A---- C:\Windows\UC.PIF
2011-04-02 17:25:13 ----A---- C:\Windows\RAR.PIF
2011-04-02 17:25:13 ----A---- C:\Windows\PKZIP.PIF
2011-04-02 17:25:13 ----A---- C:\Windows\PKUNZIP.PIF
2011-04-02 17:25:13 ----A---- C:\Windows\NOCLOSE.PIF
2011-04-02 17:25:13 ----A---- C:\Windows\LHA.PIF
2011-04-02 17:25:13 ----A---- C:\Windows\ARJ.PIF
2011-04-02 17:25:12 ----D---- C:\Users\harley1\AppData\Roaming\GHISLER
2011-04-02 17:25:12 ----D---- C:\totalcmd
2011-04-02 17:22:25 ----D---- C:\Users\harley1\AppData\Roaming\Zoner
2011-04-02 17:21:12 ----D---- C:\Program Files\Zoner
2011-04-02 17:09:01 ----D---- C:\ProgramData\Sun
2011-04-02 17:08:50 ----D---- C:\Program Files\Common Files\Java
2011-04-02 17:08:20 ----A---- C:\Windows\system32\javaws.exe
2011-04-02 17:08:20 ----A---- C:\Windows\system32\javaw.exe
2011-04-02 17:08:20 ----A---- C:\Windows\system32\java.exe
2011-04-02 17:08:20 ----A---- C:\Windows\system32\deployJava1.dll
2011-04-02 17:07:17 ----D---- C:\Program Files\Java
2011-04-02 17:05:22 ----D---- C:\Windows\system32\Macromed
2011-04-02 16:58:59 ----D---- C:\Users\harley1\AppData\Roaming\Opera
2011-04-02 16:58:49 ----D---- C:\Program Files\Opera
2011-04-02 16:56:32 ----D---- C:\Program Files\CCleaner
2011-04-02 16:55:38 ----A---- C:\Windows\mHotkey.exe
2011-04-02 16:55:38 ----A---- C:\Windows\Instit.ini
2011-04-02 16:55:38 ----A---- C:\Windows\InstIt.exe
2011-04-02 16:55:38 ----A---- C:\Windows\HKNTDLL.dll
2011-04-02 16:55:37 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-02 16:54:00 ----D---- C:\Users\harley1\AppData\Roaming\Macromedia
2011-04-02 16:53:46 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2011-04-02 16:49:05 ----A---- C:\Windows\system32\msonpmon.dll
2011-04-02 16:42:28 ----D---- C:\Program Files\Microsoft Works
2011-04-02 16:41:05 ----D---- C:\Program Files\Microsoft Visual Studio
2011-04-02 16:41:03 ----D---- C:\Program Files\Common Files\DESIGNER
2011-04-02 16:38:48 ----D---- C:\Windows\PCHEALTH
2011-04-02 16:38:47 ----D---- C:\Program Files\Microsoft.NET
2011-04-02 16:34:03 ----D---- C:\Program Files\Microsoft Visual Studio 8
2011-04-02 16:31:54 ----D---- C:\Program Files\Microsoft Office
2011-04-02 16:31:50 ----D---- C:\ProgramData\Microsoft Help
2011-04-02 16:31:06 ----RHD---- C:\MSOCache
2011-04-02 16:27:15 ----D---- C:\Users\harley1\AppData\Roaming\Adobe
2011-04-02 16:21:35 ----D---- C:\ProgramData\Adobe
2011-04-02 16:21:35 ----D---- C:\Program Files\Common Files\Adobe
2011-04-02 16:21:35 ----D---- C:\Program Files\Adobe
2011-04-02 16:06:46 ----D---- C:\Program Files\Alcohol Soft
2011-04-02 16:01:34 ----A---- C:\Windows\system32\drivers\sptd.sys
2011-04-02 15:56:13 ----D---- C:\ProgramData\Kaspersky Lab
2011-04-02 15:56:13 ----D---- C:\Program Files\Kaspersky Lab
2011-04-02 15:55:55 ----A---- C:\Windows\system32\drivers\klif.sys
2011-04-02 15:42:33 ----D---- C:\Windows\Panther
2011-04-02 15:27:39 ----N---- C:\Windows\system32\MpSigStub.exe
2011-04-02 15:22:49 ----SHD---- C:\Windows\Installer
2011-04-02 15:22:10 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2011-04-02 15:21:33 ----D---- C:\Program Files\trend micro
2011-04-02 15:21:32 ----D---- C:\rsit
2011-04-02 15:02:57 ----A---- C:\Windows\system32\NVUNINST.EXE
2011-04-02 15:02:49 ----D---- C:\Program Files\Common Files\InstallShield
2011-04-02 15:02:46 ----D---- C:\NVIDIA
2011-04-02 14:56:15 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-04-02 14:54:36 ----D---- C:\Users\harley1\AppData\Roaming\WinRAR
2011-04-02 14:54:28 ----D---- C:\Program Files\WinRAR
2011-04-02 14:52:24 ----A---- C:\Windows\system32\wintrust.dll
2011-04-02 14:52:24 ----A---- C:\Windows\system32\cabview.dll
2011-04-02 14:50:59 ----D---- C:\Users\harley1\AppData\Roaming\Identities
2011-04-02 14:50:40 ----SD---- C:\Users\harley1\AppData\Roaming\Microsoft
2011-04-02 14:50:40 ----D---- C:\Users\harley1\AppData\Roaming\Media Center Programs
2011-04-02 14:50:19 ----SHD---- C:\Recovery
2011-04-02 14:50:19 ----SHD---- C:\ProgramData\Šablony
2011-04-02 14:50:19 ----SHD---- C:\ProgramData\Plocha
2011-04-02 14:50:19 ----SHD---- C:\ProgramData\Oblíbené položky
2011-04-02 14:50:19 ----SHD---- C:\ProgramData\Nabídka Start
2011-04-02 14:50:19 ----SHD---- C:\ProgramData\Dokumenty
2011-04-02 14:50:19 ----SHD---- C:\ProgramData\Data aplikací
2011-04-02 14:47:07 ----D---- C:\Windows\SoftwareDistribution
2011-04-02 14:43:37 ----D---- C:\Windows\Prefetch
2011-04-02 14:43:28 ----SHD---- C:\System Volume Information
2011-04-02 14:43:28 ----ASH---- C:\pagefile.sys
2011-04-02 14:43:28 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 months======
2011-04-02 21:21:59 ----D---- C:\Windows\Temp
2011-04-02 21:17:13 ----D---- C:\Windows\system32\drivers
2011-04-02 21:17:10 ----HD---- C:\ProgramData
2011-04-02 21:17:01 ----RD---- C:\Program Files
2011-04-02 21:08:14 ----SHD---- C:\$Recycle.Bin
2011-04-02 20:51:14 ----D---- C:\Program Files\Common Files
2011-04-02 20:41:55 ----D---- C:\Windows
2011-04-02 20:36:13 ----RSD---- C:\Windows\Fonts
2011-04-02 20:35:25 ----D---- C:\Windows\System32
2011-04-02 20:18:49 ----D---- C:\Windows\system32\Tasks
2011-04-02 19:09:34 ----A---- C:\Windows\system32\prsgrc.dll
2011-04-02 19:04:50 ----A---- C:\Windows\system32\yvn4n82.dll
2011-04-02 19:04:45 ----A---- C:\Windows\system32\grcauth2.dll
2011-04-02 19:04:45 ----A---- C:\Windows\system32\grcauth1.dll
2011-04-02 19:04:41 ----A---- C:\Windows\system32\clauth2.dll
2011-04-02 19:04:41 ----A---- C:\Windows\system32\clauth1.dll
2011-04-02 19:04:40 ----A---- C:\Windows\system32\ssprs.dll
2011-04-02 18:10:02 ----D---- C:\Windows\Downloaded Program Files
2011-04-02 18:09:21 ----D---- C:\Windows\system32\catroot2
2011-04-02 17:58:54 ----D---- C:\Windows\system32\config
2011-04-02 17:48:37 ----D---- C:\Windows\winsxs
2011-04-02 16:50:05 ----RSD---- C:\Windows\assembly
2011-04-02 16:42:18 ----D---- C:\Program Files\Common Files\microsoft shared
2011-04-02 16:42:01 ----D---- C:\Program Files\MSBuild
2011-04-02 16:40:52 ----D---- C:\Windows\ShellNew
2011-04-02 16:38:48 ----SD---- C:\ProgramData\Microsoft
2011-04-02 16:33:10 ----A---- C:\Windows\win.ini
2011-04-02 16:33:03 ----D---- C:\Program Files\Common Files\System
2011-04-02 16:26:36 ----D---- C:\Windows\system32\DriverStore
2011-04-02 16:26:34 ----D---- C:\Windows\inf
2011-04-02 15:57:00 ----D---- C:\Windows\system32\catroot
2011-04-02 15:28:17 ----D---- C:\Windows\Microsoft.NET
2011-04-02 15:06:58 ----D---- C:\Windows\system32\wdi
2011-04-02 15:03:12 ----D---- C:\Windows\Help
2011-04-02 14:58:29 ----D---- C:\Windows\system32\CodeIntegrity
2011-04-02 14:55:28 ----D---- C:\Windows\system32\wbem
2011-04-02 14:53:25 ----D---- C:\Windows\twain_32
2011-04-02 14:52:27 ----D---- C:\Windows\system32\restore
2011-04-02 14:51:18 ----D---- C:\Windows\Logs
2011-04-02 14:50:38 ----RD---- C:\Users
2011-04-02 14:50:38 ----D---- C:\Windows\rescache
2011-04-02 14:50:19 ----D---- C:\Windows\system32\Recovery
2011-04-02 14:50:19 ----D---- C:\Program Files\Windows NT
2011-04-02 14:49:39 ----D---- C:\Windows\debug
2011-04-02 14:46:48 ----D---- C:\Windows\system32\sysprep
2011-04-02 14:44:32 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 KL1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2010-06-09 132184]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-04-02 436792]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 kl2;kl2; C:\Windows\system32\DRIVERS\kl2.sys [2010-06-09 11352]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2011-04-02 488536]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2010-04-22 22104]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2011-04-02 142592]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\Windows\system32\drivers\RTKVAC.SYS [2009-06-18 4172832]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2010-12-20 20952]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
R3 ZSMC301b;Look 312P; C:\Windows\System32\Drivers\usbVM31b.sys [2004-03-19 90968]
R4 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2010-12-20 38224]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 aitqwuhn;aitqwuhn; C:\Windows\system32\drivers\aitqwuhn.sys []
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AVP;Služba Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [2010-11-02 365336]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-12-20 363344]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-04-02 496128]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------